- Notifications
You must be signed in to change notification settings - Fork0
Bump the npm_and_yarn group across 1 directory with 26 updates#11
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.
Already on GitHub?Sign in to your account
base:main
Are you sure you want to change the base?
Uh oh!
There was an error while loading.Please reload this page.
Conversation
Bumps the npm_and_yarn group with 26 updates in the / directory:| Package | From | To || --- | --- | --- || [express](https://github.com/expressjs/express) | `4.18.2` | `4.19.2` || [markdown-it](https://github.com/markdown-it/markdown-it) | `12.0.1` | `12.3.2` || [nunjucks](https://github.com/mozilla/nunjucks) | `3.2.3` | `3.2.4` || [semver](https://github.com/npm/node-semver) | `5.7.1` | `5.7.2` || [@babel/traverse](https://github.com/babel/babel/tree/HEAD/packages/babel-traverse) | `7.21.5` | `7.25.3` || [protobufjs](https://github.com/protobufjs/protobuf.js) | `6.11.3` | `7.3.2` || [@google-cloud/appengine-admin](https://github.com/googleapis/google-cloud-node/tree/HEAD/packages/google-appengine) | `2.1.2` | `3.3.0` || [@google-cloud/cloudbuild](https://github.com/googleapis/google-cloud-node/tree/HEAD/packages/google-devtools-cloudbuild) | `2.6.0` | `4.5.0` || [@google-cloud/secret-manager](https://github.com/googleapis/google-cloud-node/tree/HEAD/packages/google-cloud-secretmanager) | `3.12.0` | `3.12.0` || [braces](https://github.com/micromatch/braces) | `3.0.2` | `3.0.3` || [gulp](https://github.com/gulpjs/gulp) | `4.0.2` | `5.0.0` || [chokidar](https://github.com/paulmillr/chokidar) | `1.7.0` | `3.5.3` || [ejs](https://github.com/mde/ejs) | `3.1.9` | `3.1.10` || [ws](https://github.com/websockets/ws) | `8.13.0` | `8.18.0` || [socket.io-client](https://github.com/socketio/socket.io-client) | `4.6.1` | `4.7.5` || [socket.io](https://github.com/socketio/socket.io) | `4.6.1` | `4.7.5` || [@lhci/cli](https://github.com/GoogleChrome/lighthouse-ci) | `0.7.2` | `0.14.0` || [puppeteer](https://github.com/puppeteer/puppeteer) | `19.11.1` | `23.1.0` || [follow-redirects](https://github.com/follow-redirects/follow-redirects) | `1.15.2` | `1.15.6` || [got](https://github.com/sindresorhus/got) | `9.6.0` | `removed` || [ava](https://github.com/avajs/ava) | `3.15.0` | `6.1.3` || [postcss](https://github.com/postcss/postcss) | `8.4.23` | `8.4.41` || [stylelint](https://github.com/stylelint/stylelint) | `13.13.1` | `16.8.2` || [stylelint-config-sass-guidelines](https://github.com/bjankord/stylelint-config-sass-guidelines) | `7.1.0` | `12.0.0` || [pug](https://github.com/pugjs/pug) | `3.0.2` | `3.0.3` || [word-wrap](https://github.com/jonschlinkert/word-wrap) | `1.2.3` | `1.2.5` |Updates `express` from 4.18.2 to 4.19.2- [Release notes](https://github.com/expressjs/express/releases)- [Changelog](https://github.com/expressjs/express/blob/master/History.md)- [Commits](expressjs/express@4.18.2...4.19.2)Updates `markdown-it` from 12.0.1 to 12.3.2- [Changelog](https://github.com/markdown-it/markdown-it/blob/master/CHANGELOG.md)- [Commits](markdown-it/markdown-it@12.0.1...12.3.2)Updates `nunjucks` from 3.2.3 to 3.2.4- [Release notes](https://github.com/mozilla/nunjucks/releases)- [Changelog](https://github.com/mozilla/nunjucks/blob/master/CHANGELOG.md)- [Commits](mozilla/nunjucks@v3.2.3...v3.2.4)Updates `semver` from 5.7.1 to 5.7.2- [Release notes](https://github.com/npm/node-semver/releases)- [Changelog](https://github.com/npm/node-semver/blob/v5.7.2/CHANGELOG.md)- [Commits](npm/node-semver@v5.7.1...v5.7.2)Updates `@babel/traverse` from 7.21.5 to 7.25.3- [Release notes](https://github.com/babel/babel/releases)- [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md)- [Commits](https://github.com/babel/babel/commits/v7.25.3/packages/babel-traverse)Updates `protobufjs` from 6.11.3 to 7.3.2- [Release notes](https://github.com/protobufjs/protobuf.js/releases)- [Changelog](https://github.com/protobufjs/protobuf.js/blob/master/CHANGELOG.md)- [Commits](protobufjs/protobuf.js@v6.11.3...protobufjs-v7.3.2)Updates `@google-cloud/appengine-admin` from 2.1.2 to 3.3.0- [Release notes](https://github.com/googleapis/google-cloud-node/releases)- [Changelog](https://github.com/googleapis/google-cloud-node/blob/main/packages/google-appengine/CHANGELOG.md)- [Commits](https://github.com/googleapis/google-cloud-node/commits/dms-v3.3.0/packages/google-appengine)Updates `@google-cloud/cloudbuild` from 2.6.0 to 4.5.0- [Release notes](https://github.com/googleapis/google-cloud-node/releases)- [Changelog](https://github.com/googleapis/google-cloud-node/blob/main/packages/google-devtools-cloudbuild/CHANGELOG.md)- [Commits](https://github.com/googleapis/google-cloud-node/commits/kms-v4.5.0/packages/google-devtools-cloudbuild)Updates `@google-cloud/secret-manager` from 3.12.0 to 3.12.0- [Release notes](https://github.com/googleapis/google-cloud-node/releases)- [Changelog](https://github.com/googleapis/google-cloud-node/blob/main/packages/google-cloud-secretmanager/CHANGELOG.md)- [Commits](https://github.com/googleapis/google-cloud-node/commits/aiplatform-v3.12.0/packages/google-cloud-secretmanager)Updates `braces` from 3.0.2 to 3.0.3- [Changelog](https://github.com/micromatch/braces/blob/master/CHANGELOG.md)- [Commits](micromatch/braces@3.0.2...3.0.3)Updates `gulp` from 4.0.2 to 5.0.0- [Release notes](https://github.com/gulpjs/gulp/releases)- [Changelog](https://github.com/gulpjs/gulp/blob/master/CHANGELOG.md)- [Commits](gulpjs/gulp@v4.0.2...v5.0.0)Updates `chokidar` from 1.7.0 to 3.5.3- [Release notes](https://github.com/paulmillr/chokidar/releases)- [Commits](paulmillr/chokidar@1.7.0...3.5.3)Updates `ejs` from 3.1.9 to 3.1.10- [Release notes](https://github.com/mde/ejs/releases)- [Commits](mde/ejs@v3.1.9...v3.1.10)Updates `ws` from 8.13.0 to 8.18.0- [Release notes](https://github.com/websockets/ws/releases)- [Commits](websockets/ws@8.13.0...8.18.0)Updates `socket.io-client` from 4.6.1 to 4.7.5- [Release notes](https://github.com/socketio/socket.io-client/releases)- [Changelog](https://github.com/socketio/socket.io-client/blob/4.7.5/CHANGELOG.md)- [Commits](socketio/socket.io-client@4.6.1...4.7.5)Updates `socket.io` from 4.6.1 to 4.7.5- [Release notes](https://github.com/socketio/socket.io/releases)- [Changelog](https://github.com/socketio/socket.io/blob/4.7.5/CHANGELOG.md)- [Commits](socketio/socket.io@4.6.1...4.7.5)Updates `@lhci/cli` from 0.7.2 to 0.14.0- [Release notes](https://github.com/GoogleChrome/lighthouse-ci/releases)- [Commits](GoogleChrome/lighthouse-ci@v0.7.2...v0.14.0)Updates `puppeteer` from 19.11.1 to 23.1.0- [Release notes](https://github.com/puppeteer/puppeteer/releases)- [Changelog](https://github.com/puppeteer/puppeteer/blob/main/release-please-config.json)- [Commits](puppeteer/puppeteer@puppeteer-v19.11.1...puppeteer-v23.1.0)Updates `follow-redirects` from 1.15.2 to 1.15.6- [Release notes](https://github.com/follow-redirects/follow-redirects/releases)- [Commits](follow-redirects/follow-redirects@v1.15.2...v1.15.6)Removes `got`Updates `ava` from 3.15.0 to 6.1.3- [Release notes](https://github.com/avajs/ava/releases)- [Commits](avajs/ava@v3.15.0...v6.1.3)Updates `postcss` from 8.4.23 to 8.4.41- [Release notes](https://github.com/postcss/postcss/releases)- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)- [Commits](postcss/postcss@8.4.23...8.4.41)Updates `stylelint` from 13.13.1 to 16.8.2- [Release notes](https://github.com/stylelint/stylelint/releases)- [Changelog](https://github.com/stylelint/stylelint/blob/main/CHANGELOG.md)- [Commits](stylelint/stylelint@13.13.1...16.8.2)Updates `stylelint-config-sass-guidelines` from 7.1.0 to 12.0.0- [Release notes](https://github.com/bjankord/stylelint-config-sass-guidelines/releases)- [Changelog](https://github.com/bjankord/stylelint-config-sass-guidelines/blob/main/CHANGELOG.md)- [Commits](bjankord/stylelint-config-sass-guidelines@v7.1.0...v12.0.0)Updates `pug` from 3.0.2 to 3.0.3- [Release notes](https://github.com/pugjs/pug/releases)- [Commits](https://github.com/pugjs/pug/compare/pug@3.0.2...pug@3.0.3)Updates `socket.io` from 4.6.1 to 4.7.5- [Release notes](https://github.com/socketio/socket.io/releases)- [Changelog](https://github.com/socketio/socket.io/blob/4.7.5/CHANGELOG.md)- [Commits](socketio/socket.io@4.6.1...4.7.5)Updates `word-wrap` from 1.2.3 to 1.2.5- [Release notes](https://github.com/jonschlinkert/word-wrap/releases)- [Commits](jonschlinkert/word-wrap@1.2.3...1.2.5)---updated-dependencies:- dependency-name: express dependency-type: direct:production dependency-group: npm_and_yarn- dependency-name: markdown-it dependency-type: direct:production dependency-group: npm_and_yarn- dependency-name: nunjucks dependency-type: direct:production dependency-group: npm_and_yarn- dependency-name: semver dependency-type: indirect dependency-group: npm_and_yarn- dependency-name: "@babel/traverse" dependency-type: indirect dependency-group: npm_and_yarn- dependency-name: protobufjs dependency-type: indirect dependency-group: npm_and_yarn- dependency-name: "@google-cloud/appengine-admin" dependency-type: direct:production dependency-group: npm_and_yarn- dependency-name: "@google-cloud/cloudbuild" dependency-type: direct:production dependency-group: npm_and_yarn- dependency-name: "@google-cloud/secret-manager" dependency-type: direct:development dependency-group: npm_and_yarn- dependency-name: braces dependency-type: indirect dependency-group: npm_and_yarn- dependency-name: gulp dependency-type: direct:production dependency-group: npm_and_yarn- dependency-name: chokidar dependency-type: direct:production dependency-group: npm_and_yarn- dependency-name: ejs dependency-type: indirect dependency-group: npm_and_yarn- dependency-name: ws dependency-type: indirect dependency-group: npm_and_yarn- dependency-name: socket.io-client dependency-type: indirect dependency-group: npm_and_yarn- dependency-name: socket.io dependency-type: indirect dependency-group: npm_and_yarn- dependency-name: "@lhci/cli" dependency-type: direct:production dependency-group: npm_and_yarn- dependency-name: puppeteer dependency-type: direct:development dependency-group: npm_and_yarn- dependency-name: follow-redirects dependency-type: indirect dependency-group: npm_and_yarn- dependency-name: got dependency-type: indirect dependency-group: npm_and_yarn- dependency-name: ava dependency-type: direct:development dependency-group: npm_and_yarn- dependency-name: postcss dependency-type: indirect dependency-group: npm_and_yarn- dependency-name: stylelint dependency-type: direct:development dependency-group: npm_and_yarn- dependency-name: stylelint-config-sass-guidelines dependency-type: direct:development dependency-group: npm_and_yarn- dependency-name: pug dependency-type: indirect dependency-group: npm_and_yarn- dependency-name: socket.io dependency-type: indirect dependency-group: npm_and_yarn- dependency-name: word-wrap dependency-type: indirect dependency-group: npm_and_yarn...Signed-off-by: dependabot[bot] <support@github.com>
New and removed dependencies detected. Learn more aboutSocket for GitHub ↗︎
🚮 Removed packages:npm/@google-cloud/appengine-admin@2.1.2,npm/@google-cloud/cloudbuild@2.6.0,npm/@lhci/cli@0.7.2,npm/ava@3.15.0,npm/express@4.18.2,npm/gulp@4.0.2 |
🚨 Potential security issues detected. Learn more aboutSocket for GitHub ↗︎ To accept the risk, merge this PR and you will not be notified again.
Next stepsWhat is an install script?Install scripts are run when the package is installed. The majority of malware in npm is hidden in install scripts. Packages should not be running non-essential scripts during install and there are often solutions to problems people solve with install scripts that can be run at publish time instead. Take a deeper look at the dependencyTake a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support [AT] socket [DOT] dev. Remove the packageIf you happen to install a dependency that Socket reports asKnown Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency. Mark a package as acceptable riskTo ignore an alert, reply with a comment starting with
|
Bumps the npm_and_yarn group with 26 updates in the / directory:
4.18.24.19.212.0.112.3.23.2.33.2.45.7.15.7.27.21.57.25.36.11.37.3.22.1.23.3.02.6.04.5.03.12.03.12.03.0.23.0.34.0.25.0.01.7.03.5.33.1.93.1.108.13.08.18.04.6.14.7.54.6.14.7.50.7.20.14.019.11.123.1.01.15.21.15.69.6.0removed3.15.06.1.38.4.238.4.4113.13.116.8.27.1.012.0.03.0.23.0.31.2.31.2.5Updates
expressfrom 4.18.2 to 4.19.2Release notes
Sourced fromexpress's releases.
... (truncated)
Changelog
Sourced fromexpress's changelog.
Commits
04bc6274.19.2da4d763Improved fix for open redirect allow list bypass4f0f6cc4.19.1a003cfaAllow passing non-strings to res.location with new encoding handling checks f...a1fa90ffixed un-edited version in history.md for 4.19.011f2b1dbuild: fix build due to inconsistent supertest behavior in older versions084e3654.19.00867302Prevent open redirect allow list bypass due to encodeurl567c9c6Add note on how to update docs for new release (#5541)69a4cf2deps: cookie@0.6.0Maintainer changes
This version was pushed to npm bywesleytodd, a new releaser for express since your current version.
Updates
markdown-itfrom 12.0.1 to 12.3.2Changelog
Sourced frommarkdown-it's changelog.
... (truncated)
Commits
d72c68b12.3.2 releasedaca3396dist rebuildffc49abFix possible ReDOS in newline rule.76469e812.3.1 releasedae5a243dist rebuild1cd8a51Fix tab preventing paragraph continuation in lists830757cFix spelling error in question Github Template (#835)2e31d3412.3.0 released393354cDist rebuild8564eedDev deps bumpUpdates
nunjucksfrom 3.2.3 to 3.2.4Release notes
Sourced fromnunjucks's releases.
Changelog
Sourced fromnunjucks's changelog.
Commits
86a77f4Release v3.2.4ec16d21fix: html encode backslashes if used with escape filter or autoescape (#1437)Updates
semverfrom 5.7.1 to 5.7.2Release notes
Sourced fromsemver's releases.
Changelog
Sourced fromsemver's changelog.
Commits
f8cc313chore: release 5.7.22f8fd41fix: better handling of whitespace (#585)deb5ad5chore:@npmcli/template-oss@4.16.0Maintainer changes
This version was pushed to npm bylukekarrys, a new releaser for semver since your current version.
Updates
@babel/traversefrom 7.21.5 to 7.25.3Release notes
Sourced from
@babel/traverse's releases.... (truncated)
Changelog
Sourced from
@babel/traverse's changelog.... (truncated)
Commits
787c7cdv7.25.3992c6e0Avoid validating visitors produced bytraverse.visitors.merge(#16699)44efb5fprint@babel/traverseversion on unknown AST types (#16701)0f8f408v7.25.26a15d7aEnsure thatrequeueComputedKeyAndDecoratorsis available (#16695)2413d1aAdd eslint-plugin-regexp (#16680)6bfc823v7.25.1801d3cbfix: improve variable declarator removal (#16587)d2e3ee2v7.25.0d364545MoveensureFunctionNametoNodePath.prototype(#16658)Updates
protobufjsfrom 6.11.3 to 7.3.2Release notes
Sourced fromprotobufjs's releases.
... (truncated)
Changelog
Sourced fromprotobufjs's changelog.
... (truncated)
Commits
0a0cdb6chore: release master (#2005)0f9d477fix(docs): Update readme to correct command for creating types (#1939)a71ef76chore: release master (#2002)d1d2c0cfix(types): reserved field in IType can contain reserved names (#2001)11393eachore: Renovate README.md (#1995)722b635chore: release master (#1991)2d58011feat: add handling for extension range options (#1990)2f846fechore: release master (#1962)af3ff83fix: report missing import properly in loadSync (#1960)4436cc7chore: release master (#1925)Updates
@google-cloud/appengine-adminfrom 2.1.2 to 3.3.0Release notes
Sourced from
@google-cloud/appengine-admin's releases.Changelog
Sourced from
@google-cloud/appengine-admin's changelog.... (truncated)
Commits
45aa7f1chore(deps): update dependency gapic-tools to v0.4.0 (#5104)e7b43e8chore: upgrade c8 to v9 (#5066)f49589cchore: release main (#5030)b6498d8feat: Trusted Private Cloud support, use the universeDomain parameter (#5022)9bb3b37chore(deps): update dependency gapic-tools to v0.3.0 (#4958)4b0b1f9chore: update copyright year (#4909)fe7dc9echore: remove compile-protos from prepare script (#4829)31d107bchore(deps): update dependency@types/sinonto v17 (#4791)362152echore(deps): update dependency sinon to v17 (#4754)4b6ac7dchore(deps): update dependency pack-n-play to v2 (#4716)Updates
@google-cloud/cloudbuildfrom 2.6.0 to 4.5.0Release notes
Sourced from
@google-cloud/cloudbuild's releases.... (truncated)
Changelog
Sourced from
@google-cloud/cloudbuild's changelog.... (truncated)
Commits
18c40f4build: [Many APIs] update gapic generator to allow individual location mixin ...aed952echore(deps): update dependency sinon to v18 (#5365)30376f3chore: release main (#5363)a4ab109chore: [Many APIs] update copyright year (#5329)5067a61chore: release main (#5181)b926f13feat: [Many APIs] add several fields to manage state of database encryption u...054cb8achore: release main (#5136)334e7b9feat: [cloudbuild] Add Bitbucket Data Center Config and Bitbucket Cloud confi...45aa7f1chore(deps): update dependency gapic-tools to v0.4.0 (#5104)e7b43e8chore: upgrade c8 to v9 (#5066)Updates
@google-cloud/secret-managerfrom 3.12.0 to 3.12.0Changelog
Sourced from
@google-cloud/secret-manager's changelog.Commits
Updates
bracesfrom 3.0.2 to 3.0.3Commits
74b2db23.0.388f1429update eslint. lint, fix unit tests.415d660Snyk js braces6838727 (#40)190510ffix tests, skip 1 test in test/braces.expand716eb9freadme bumpa5851e5Merge pull request#37 from coderaiser/fix/vulnerability2092bd1feature: braces: add maxSymbols (https://github.com/micromatch/braces/issues/...9f5b4cffix: vulnerability (https://security.snyk.io/vuln/SNYK-JS-BRACES-6838727)98414f9remove funding file665ab5dupdate keepEscaping doc (Description has been truncated